Privacy Policy
How Endcap collects, uses, and protects personal data, for visitors to this site, people who enquire about a trial, and the agencies and clients who use the product.
This is a working draft published for transparency and is not legal advice. It should be reviewed by a qualified data-protection adviser before launch. Items marked [to confirm] still need finalised details.
Last updated: 20 June 2026
Who we are
Endcap is field-marketing software for agencies and brands. This policy applies to our marketing website at www.getendcap.com, to enquiries you send us, and to the Endcap product at app.getendcap.com.
For the personal data described in this policy, the data controller is Endcap, Inc. [to confirm]: registered company details and the postal address for privacy correspondence. Endcap provides a business-to-business service to customers in the US, the UK, and the EU.
Where you are a customer of Endcap, you act as the data controller for the personal data you and your reps put into the product about your clients, stores, and field activity, and Endcap acts as your data processor. Those arrangements are governed by a Data Processing Addendum, available on request from privacy@getendcap.com. This privacy policy describes the personal data for which Endcap is the controller.
What we collect
Website visitors and the contact / trial enquiry form
When you complete our contact or trial enquiry form, we collect the information you provide: your first and last name, your work email address, your company name, your role, the number of demos you run per month, and any message you write. We use a hidden anti-spam field (a honeypot) to filter out automated submissions. These enquiries are delivered to our sales inbox.
Account and product data
When your organisation uses Endcap, we process account data such as the names, email addresses, and roles of the people you invite (managers, reps, and client viewers), together with the field-marketing data you create: campaigns, events, submissions, photos, store and client records, and reports. Personal data may appear in this content where you choose to include it. For this data, you are the controller and Endcap is your processor.
Usage and log data
When you use the website or the product, our hosting and infrastructure providers automatically record technical information such as your IP address, request logs, the pages or actions requested, browser and device information, and timestamps. We use this to keep the service secure and available, to investigate problems and abuse, and to enforce rate limits.
Cookies and tracking
The Endcap marketing website sets no tracking or analytics cookies and loads no third-party advertising or analytics trackers. The Endcap product uses only the strictly necessary cookies and storage required to keep you signed in and to operate the service securely.
Our lawful bases for processing
Under the UK GDPR and the EU GDPR we rely on the following lawful bases, depending on the circumstances:
- Contract: to provide the product and account to a customer, to respond to a trial enquiry, and to administer billing and support.
- Legitimate interests: to respond to business enquiries, to keep the service secure and reliable, to prevent fraud and abuse, and to improve our service.
- Consent: where we ask for it, for example before sending optional marketing communications. You can withdraw consent at any time.
- Legal obligation: where we must process data to comply with the law, for example certain accounting and tax records.
How we use personal data
- To respond to your enquiries and arrange and run trials and demos.
- To provide, maintain, secure, and support the Endcap product and your account.
- To process payments and manage subscriptions for paying customers.
- To send service messages about your account, security, or changes to the service.
- To detect, prevent, and investigate abuse, fraud, and security incidents, and to comply with our legal obligations.
We do not sell personal data, and we do not use your enquiry or account data to train AI models. Endcap's AI features (such as Ask Endcap and AI report summaries) work only over your own organisation's data and keep it scoped to your organisation. To generate these insights, the relevant submission and report text is sent to a third-party AI sub-processor, Anthropic, which processes it on our behalf under contract and does not use it to train its models. An organisation administrator can opt out of these AI features, in which case this content is not sent to that sub-processor.
Sharing and sub-processors
We share personal data with a small set of trusted service providers who process it on our behalf under written contracts, for example for hosting, our database and storage, email delivery, payments, rate limiting, and AI/LLM insight generation (Anthropic). We require each of them to protect personal data and to use it only to provide their service to us. A current list of sub-processors is available on request from privacy@getendcap.com.
We may also disclose personal data where required by law, to establish or defend legal claims, or in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honour this policy.
International transfers
Some of our sub-processors process data in the United States or other countries. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards, such as the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, so your data continues to receive an essentially equivalent level of protection. [to confirm]: the specific transfer mechanism in place with each US sub-processor.
How long we keep data
We keep personal data only for as long as we need it for the purposes set out above. Enquiry data is kept for as long as needed to follow up and for our legitimate business records. Customer account and product data is kept for the life of the account and for a limited period afterwards, unless a longer period is required by law. Security and request logs are kept for a short period for operational and security purposes. [to confirm]: specific retention periods.
Your rights
Subject to the conditions in data-protection law, you have the right to access the personal data we hold about you; to have inaccurate data corrected; to have your data erased in certain circumstances; to restrict or object to certain processing; to receive your data in a portable format; and to withdraw consent at any time where we rely on it.
To exercise any of these rights, email privacy@getendcap.com. Where Endcap processes data on behalf of a customer, we will direct your request to that customer. You also have the right to complain to your local data-protection authority, although we would welcome the chance to address your concerns first.
Security
We take the security of personal data seriously. Measures include row-level data isolation between organisations, access controls enforced in the database, audit logging, stripping of EXIF and GPS metadata from uploaded photos, and signed-URL storage for files. For more detail, see our security page. No method of transmission or storage is completely secure, but we work to protect your data using appropriate technical and organisational measures.
Children
Endcap is a business service and is not directed to children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact us so we can remove it.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "last updated" date above and, where appropriate, notify customers. Please review this page periodically.
Contact us
For any privacy question, or to exercise your rights, email privacy@getendcap.com, or reach us through our contact page.